---
title: "Create a link token to verify an external account"
method: POST
path: "/external_accounts/link_tokens"
tags: ["External Accounts"]
---

# Create a link token to verify an external account

`POST /external_accounts/link_tokens`

## Headers

- `Idempotency-Key` string

## Request body

- ExternalAccountLinkToken
  - `business_id` string, uuid — The identifier for the business customer associated with this external account. Exactly one of `business_id` or `customer_id` must be specified.
  - `client_name` string, required — The name of your application, as it should be displayed in Link. Maximum length of 30 characters.
  - `country_codes` string[], required — Country codes in the ISO-3166-1 alpha-2 country code standard.
  - `customer_id` string, uuid — The identifier for the personal customer associated with this external account. Exactly one of `customer_id` or `business_id` must be specified.
  - `expiration` string, date-time — The expiration date for the link_token. Expires in 4 hours.
  - `language` 'DE' | 'EN' | 'ES' | 'FR' | 'NL', required — The language that corresponds to the link token. For Plaid, see their [documentation](https://plaid.com/docs/api/tokens/#link-token-create-request-language) for a list of allowed values.
  - `link_customization_name` string — The name of the Link customization from the Plaid Dashboard to be applied to Link. If not specified, the default customization will be used. When using a Link customization, the language in the customization must match the language selected via the language parameter, and the countries in the customization should match the country codes selected via country_codes.
  - `link_token` string — A link_token, which can be supplied to Link in order to initialize it and receive a public_token, which can be exchanged for an access_token.
  - `redirect_uri` string — A URI indicating the destination where a user should be forwarded after completing the Link flow; used to support OAuth authentication flows when launching Link in the browser or via a webview.
  - `request_id` string — A unique identifier for the request, which can be used for troubleshooting.
  - `sdk_type` 'ANDROID' | 'IOS' | 'WEB' — Describes the environment of the client code running a vendor-supplied SDK
  - `type` 'CREDIT' | 'DEPOSITORY' | 'INVESTMENT' | 'MICRO_DEPOSIT', required — The type of the link token. DEPOSITORY for checking and savings accounts, CREDIT for credit card type accounts, INVESTMENT for investment accounts, and MICRO_DEPOSIT for depository accounts with support for micro-deposits verification.
  - `vendor_access_token` string — The access token associated with the Item data is being requested for.
  - `vendor_institution_id` string — The ID of the institution the access token is requested for. If present the link token will be created in an update mode.
  - `verify_owner` boolean — If true, Synctera will attempt to verify that the external account owner is the same as the customer by comparing external account data to customer data. At least 2 of the following fields must match: name, phone number, email, address. Verification is disabled by default.

## Response `201`

New verification link token

- ExternalAccountLinkToken
  - `business_id` string, uuid — The identifier for the business customer associated with this external account. Exactly one of `business_id` or `customer_id` must be specified.
  - `client_name` string, required — The name of your application, as it should be displayed in Link. Maximum length of 30 characters.
  - `country_codes` string[], required — Country codes in the ISO-3166-1 alpha-2 country code standard.
  - `customer_id` string, uuid — The identifier for the personal customer associated with this external account. Exactly one of `customer_id` or `business_id` must be specified.
  - `expiration` string, date-time — The expiration date for the link_token. Expires in 4 hours.
  - `language` 'DE' | 'EN' | 'ES' | 'FR' | 'NL', required — The language that corresponds to the link token. For Plaid, see their [documentation](https://plaid.com/docs/api/tokens/#link-token-create-request-language) for a list of allowed values.
  - `link_customization_name` string — The name of the Link customization from the Plaid Dashboard to be applied to Link. If not specified, the default customization will be used. When using a Link customization, the language in the customization must match the language selected via the language parameter, and the countries in the customization should match the country codes selected via country_codes.
  - `link_token` string — A link_token, which can be supplied to Link in order to initialize it and receive a public_token, which can be exchanged for an access_token.
  - `redirect_uri` string — A URI indicating the destination where a user should be forwarded after completing the Link flow; used to support OAuth authentication flows when launching Link in the browser or via a webview.
  - `request_id` string — A unique identifier for the request, which can be used for troubleshooting.
  - `sdk_type` 'ANDROID' | 'IOS' | 'WEB' — Describes the environment of the client code running a vendor-supplied SDK
  - `type` 'CREDIT' | 'DEPOSITORY' | 'INVESTMENT' | 'MICRO_DEPOSIT', required — The type of the link token. DEPOSITORY for checking and savings accounts, CREDIT for credit card type accounts, INVESTMENT for investment accounts, and MICRO_DEPOSIT for depository accounts with support for micro-deposits verification.
  - `vendor_access_token` string — The access token associated with the Item data is being requested for.
  - `vendor_institution_id` string — The ID of the institution the access token is requested for. If present the link token will be created in an update mode.
  - `verify_owner` boolean — If true, Synctera will attempt to verify that the external account owner is the same as the customer by comparing external account data to customer data. At least 2 of the following fields must match: name, phone number, email, address. Verification is disabled by default.

## Other responses

- `400` — BadRequest
- `401` — Unauthorized
- `403` — Forbidden error
- `500` — Internal server error

---

[API](https://skmtc.net/synctera/apis/synctera-api.md) · [All operations](https://skmtc.net/synctera/apis/synctera-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/synctera/synctera-api/revisions/b0d812e6cdd0/schema)
